NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #946 most downloaded on PyPI
Windows Negotiate Authentication Client and Server
Last release 5 days ago
29 Sep 2026
Release timing varies
gaps range from 4 weeks to 10 months
Nearly every release is documented
notes for 33 of 33 stable releases
2 versions withdrawn
withdrawn after publishing
6 years old
40 releases · first in 2020
One column per quarter.
Fix NTLM acceptor to include the Version field in the CHALLENGE message when NTLMSSP_NEGOTIATE_VERSION is negotiated
Version field in the CHALLENGE message when NTLMSSP_NEGOTIATE_VERSION is negotiated
gss-ntlmssp failed to decode the message as the field offsets were 8 bytes too earlyFull Changelog: v0.12.2...v0.12.3
Fix up NTLM single host data unpacking to be less strict making it compatible with newer Windows versions
kinit operation, this avoid issues around not being able to find TGT in cache during Kerberos authenticationFull Changelog: v0.12.1...v0.12.2
Fix up NTLM Single Host unpacking by @jborean93 in #102
Full Changelog: v0.12.0...v0.12.1
TargetInfo contains extra data for Single_Host_Data
Update build deps and update Python versions by @jborean93 in #98
KerberosKeytab on SSPI/Windows with Kerberos authenticationspnego.server using the credentials kwarg. This currently only works on Windows/SSPI when specifying a keytab credential for the serviceFull Changelog: v0.11.2...v0.12.0
Fix CredSSP acceptor with LibreSSL by @jborean93 in #92
Full Changelog: v0.11.1...v0.11.2
Fix deprecation warning for Cryptography 44.0.0 or newer by @hamarituc in #87
ARC4 cipher from the new decrepits module sub-package, this removes the warning issued in newer versions of the cryptography libraryFull Changelog: v0.11.0...v0.11.1
Stop using deprecated datetime.dateime.utcnow() for CredSSP acceptor context
surrogatepass error option
datetime.dateime.utcnow() for CredSSP acceptor contextNone is kept as use the cached credentialFull Changelog: v0.10.2...v0.11.0
Rename sspic to sspilib by @jborean93 in #72
sspi package dependency to sspilibRename sspi dep to sspic by @jborean93 in #70
sspi package dependency to sspic to avoid conflicts with pywin32Migrate SSPI to external library by @jborean93 in #69
sspi
sspi package improves performance and memory allocation with a more robust APIFull Changelog: v0.9.2...v0.10.0
Added Python 3.12 win wheels and test in CI by @jborean93 in #67
Full Changelog: v0.9.1...v0.9.2
Set NTLM Negotiate Version field by @jborean93 in #65
NTLMSSP_REQUEST_VERSION flag on the NTLM Negotiate message
Full Changelog: v0.9.0...v0.9.1
Added the spnego.ContextReq.dce_style flag to enable DCE authentication mode
spnego.ContextReq.dce_style flag to enable DCE authentication mode
spnego.iov.BufferType.sign_only on SSPI has changed from representing SECBUFFER_MECHLIST to SECBUFFER_READONLY_WITH_CHECKSUM
sign_only means when using it with GSSAPISECBUFFER_MECHLIST is not seen in any examples in the wild and is most likely an internal flagspnego.iov.BufferType.data_readonly
SECBUFFER_DATA | SECBUFFER_READONLYGSS_IOV_BUFFER_TYPE_EMPTYwrap_iov and unwrap_iov in the Python NTLM context provider.
spnego.iov.BufferType.header, spnego.iov.BufferType.data, spnego.iov.BufferType.sign_only, spnego.iov.BufferType.data_readonly, and spnego.iov.BufferType.streamheader
wrap_iov: Used to place the resulting signature in the bufferunwrap_iov: Used as the signature source for validationdata
wrap_iov: Data to be encrypted/sealedunwrap_iov: Data to be decrypted/unsealedsign_only
wrap_iov: Data to be included in the signature/header generationunwrap_iov: Data to be included in the signature/header verificationdata_readonly is treated the same as sign_onlystream
wrap_iov: Not supportedunwrap_iov: Contains the full value to decrypt with the headers in the beginning, must be coupled with a subsequent data buffer of the type data to place the decrypted value intoSSPI works but not all the permutations have been tested.data, sign_only, data_readonly values concat together in the order they are provided.query_message_sizes() function on a context to retrieve the important message sizes
header, also known as the signature or security trailerAdded the spnego.ContextReq.no_integrity flag to disable integrity/confidentiality on Kerberos/Negotiate contexts
spnego.ContextReq.no_integrity flag to disable integrity/confidentiality on Kerberos/Negotiate contexts
GSS-SPNEGO where the context flags control the SSF flagsstep() on a security context channel_bindings
Added support for decoding the following TLS payloads with python -m spnego --token ...
python -m spnego --token ...
new_context() method on the context proxies to provide an easy and efficient way to re-use the context credentials and options for a new contextgssntlmssp to simplify codebase and ensure a consistent experience across OS versions
Ignore GSS_S_NO_CONTEXT errors on GSSAPI after stepping through the token exchange before the context is complete
GSS_S_NO_CONTEXT errors on GSSAPI after stepping through the token exchange before the context is complete
Fix up sdist and wheels to include py.typed type annotation marker
py.typed type annotation marker* Added Python 3.11 wheel
Drop support for Python 3.6 - new minimum is 3.7+
pyproject.toml and made Cython a build requirement for Windows
Fix str of enum values when running in Python 3.11 to be consistent with older versions
gssapi on 1.5.x which comes with RHEL 8.Fix heap allocation errors when running with heap allocation monitoring on Windows
Added custom MD4 hashing code for NTLM to use.
hashlib.new('md4', b"")Call gss_inquire_sec_context_by_oid(ctx, spnego_req_mechlistMIC_oid) when using pure NTLM over GSSAPI to ensure the token contains a MIC
gss_inquire_sec_context_by_oid(ctx, spnego_req_mechlistMIC_oid) when using pure NTLM over GSSAPI to ensure the token contains a MICThis can be set to 5+ to ensure the peer supports and applies the mitigations for CVE-2018-0886.
auth_stage extra_info for a CredSSP context to give a human friendly indication of what sub auth stage it is up to.protocol_version extra_info for a CredSSP context to return the negotiated CredSSP protocol version.credssp_min_protocol keyword argument for a CredSSP context to set a minimum version the caller will accept of the peer.
5+ to ensure the peer supports and applies the mitigations for CVE-2018-0886.NegotiateProxy before any contexts have been set up (https://github.com/jborean93/pyspnego/issues/33)The username and password property on the auth context object are deprecated and will return None until it is removed in a future release
usage argument for tls.default_tls_context to control whether the context is for a initiator or acceptorpy.typed in the package for downstream library useContextProxy class for type annotation useget_extra_info to ContextProxy to expose a common way to retrieve context specific information, this is currently used by CredSSP to retrieve
client_credential: The delegated client credential for acceptors once the context is completesslcontext: The SSL context used to create the TLS objectssl_object: The TLS object used during the CredSSP exchangeclient_credential property on CredSSP has been removed in favour of `context.get_extra_info('client_credential')pyspnego's Negotiate proxy context
username and password property on the auth context object are deprecated and will return None until it is removed in a future releaseDo not convert GSSAPI service to lowercase for GSSAPI and uppercase for SSPI
Changed project structure to a src layout
src layoutpyx/pyd and C files for SSPI in the sdist generatedInvalidTokenError rather than struct.errorA deprecation warning is raised when importing from these package directly and this will be removed in the next major release
gss, negotiate, ntlm, sspi exports private, use the spnego.client and spnego.server functions instead
protocol='credssp'spnego.client and spnego.server to control authentication specific optionsmechListMIC if it contains the same value as the responseToken due to an old Windows SPNEGO logic bug - https://github.com/krb5/krb5/blob/3f5a348287646d65700854650fe668b9c4249013/src/lib/gssapi/spnego/spnego_mech.c#L3734-L3744auth='ntlm' and the password is in the form {lm_hash}:{nt_hash}This will be the last release that supports Python 2.7 and 3.5
iov.BufferType to IntEnum to fix load on Python 3.10 - https://github.com/jborean93/pyspnego/issues/10pyspnego-parse and entry point which uses __main__.py in the spnego package
python -m spnego --token ...Respect NETBIOS_COMPUTER_NAME when getting the workstation name for NTLM tokens. This matches the behaviour of gss-ntlmssp to ensure a consistent appr
NETBIOS_COMPUTER_NAME when getting the workstation name for NTLM tokens. This matches the behaviour of gss-ntlmssp to ensure a consistent approach.Only send negState: request-mic for the first reply from an acceptor for Negotiate auth.
negState: request-mic for the first reply from an acceptor for Negotiate auth.
Added Python 3.9 to CI and build Windows wheel for this version
* Fix up WinRM wrapping on SSPI
Include the cython files in the built sdist
Added the wrap_winrm and unwrap_winrm methods to a context to cover the complexity of WinRM wrapping
Initial release of pyspnego
wrap_winrm and unwrap_winrm methods to a context to cover the complexity of WinRM wrappingContextReq.delegate_policy and just make it optional based on the python-gssapi version installedContextReq.delegate_policy because python-gssapi does not support flags that they do not defineforwardable flags set when ContextReq.delegate is requestedpyspnego-parse help messages a bit moreyaml extras group to install ruamel.yaml which is an optional feature for pyspengo-parselinetrace=True which breaks debugging in PyCharmFirst beta release of pyspnego.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →